Title | CySec Game: A Framework and Tool for Cyber Risk Assessment and Security Investment Optimization in Critical Infrastructures |
Publication Type | Conference Paper |
Year of Publication | 2022 |
Authors | Hyder, Burhan, Majerus, Harrison, Sellars, Hayden, Greazel, Jonathan, Strobel, Joseph, Battani, Nicholas, Peng, Stefan, Govindarasu, Manimaran |
Conference Name | 2022 Resilience Week (RWS) |
Keywords | attack-defense tree, CPS, critical infrastructure, cybersecurity, game theoretic security, game theory, Games, Human Behavior, human factors, Metrics, pubcrawl, remote monitoring, risk assessment, risk management, Scalability, Smart grids, Software algorithms, software tools |
Abstract | Cyber physical system (CPS) Critical infrastructures (CIs) like the power and energy systems are increasingly becoming vulnerable to cyber attacks. Mitigating cyber risks in CIs is one of the key objectives of the design and maintenance of these systems. These CPS CIs commonly use legacy devices for remote monitoring and control where complete upgrades are uneconomical and infeasible. Therefore, risk assessment plays an important role in systematically enumerating and selectively securing vulnerable or high-risk assets through optimal investments in the cybersecurity of the CPS CIs. In this paper, we propose a CPS CI security framework and software tool, CySec Game, to be used by the CI industry and academic researchers to assess cyber risks and to optimally allocate cybersecurity investments to mitigate the risks. This framework uses attack tree, attack-defense tree, and game theory algorithms to identify high-risk targets and suggest optimal investments to mitigate the identified risks. We evaluate the efficacy of the framework using the tool by implementing a smart grid case study that shows accurate analysis and feasible implementation of the framework and the tool in this CPS CI environment. |
DOI | 10.1109/RWS55399.2022.9984040 |
Citation Key | hyder_cysec_2022 |